Prerequisites

Prerequisites

Before deployment, confirm that the Apporto instance, infrastructure, network, certificate, and policy prerequisites are complete. Use this page to collect required values, validate platform readiness, and identify any approvals needed before implementation begins.

Apporto currently supports Windows 11 and Windows Server hosts for desktop and application workloads. Note as a Microsoft restriction that when using Windows 11 in any On-Prem configuration, only a Single-Session can be used and launched to each VM.

Linux VM configuration is also supported where applicable.

Instance readiness

After your Apporto license is executed, Apporto provisions your instance using the instance name and URL agreed on during onboarding. Apporto Support then provides the initial control plane administrator login so you can configure the instance, authentication, and desktops.

  • Confirm the final Apporto instance name and URL.

  • Identify the initial administrator and any additional local administrators.

  • Plan identity management integration before production rollout.

Related help articles:

Readiness checklist

Complete this checklist before scheduling installation or production cutover.

Readiness item

Required value or decision

Owner

Status

Readiness item

Required value or decision

Owner

Status

Static IP addresses

Static IP for each Apporto appliance, worker node, gateway, load balancer, and workload VM as applicable.

Network team

Not started

FQDNs and DNS records

Public or internal FQDNs for the Apporto instance, hyperstream endpoints, gateway, and load balancer.

Network or DNS team

Not started

SSL certificates

Certificate files, private key, certificate chain, and renewal owner for each endpoint.

Security or PKI team

Not started

Firewall approval

Approved ingress and egress rules for management, user traffic, DNS, NTP, directory services, RDP, and hypervisor APIs.

Network or security team

Not started

Selected hypervisor

VMware vSphere, Nutanix Prism, Proxmox Virtual Environment, Hyper-V Server, or physical servers.

Infrastructure team

Not started

Active Directory

Our Minimum Auth usage is using MS AD.

Customer AD Team

Not started

MS RDS\TS Cals

Customer responsible for all MS Windows RDS\TS CAL License requirements

Customer License Team

Not started

Component requirements

Browser compatibility

Apporto runs applications and desktops through an HTML5/WebGL-compatible browser. Apporto validates the latest releases of Google Chrome, Firefox, Safari, and Microsoft Edge.

Google Chrome is recommended for optimal performance.

Apporto components

The following table lists the minimum requirements for the Apporto NextGen on-premises components.

Apporto component

Minimum each

Required

Apporto manager node

4 vCPU, 8 GB RAM, 50 GB OS disk, 50 GB data disk

One per cluster

Apporto worker nodes

4 vCPU, 12 GB RAM, 50 GB OS disk, 50 GB data disk

At least Three per cluster

HAProxy

2 vCPU, 4-6 GB RAM, 50-60 GB disk

2 Node\VMs. Required if you are not using your own load balancer or content delivery controller

Workloads and sizing guidelines

For RDS and VDI workload sizing, Apporto recommends using Microsoft’s VM sizing guidance: https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/virtual-machine-recs

Hypervisors

Apporto NextGen can run in a virtualized environment or on physical servers. Virtualized environments are recommended because they support snapshots, automation, and repeatable VM creation.

Physical servers are typically needed only when presenting physical GPU cards without the performance impact or licensing considerations associated with hypervisor passthrough.

Apporto validates the following hypervisors.

Hypervisor

Supported by Apporto

VMware vSphere

Versions 6.5, 7.x, 8.0

Nutanix Prism

Operating system 6.5+

Proxmox Virtual Environment

Version 8.0+, 9.0+

Hyper-V Server

Server 2025; Gen 1 nodes only

Plan capacity for VDI/RDS growth and Apporto node cluster expansion as adoption increases. New deployments should also include a backup and disaster recovery plan.

Some features might not be supported on all hypervisor platforms or versions. See the feature documentation for details.

Networking

IP addresses

Assign a static IP address to each deployed component during configuration.

Fully qualified domain names (FQDNs)

Configure FQDNs for the hyperstream endpoints that connect to your load balancer or gateway, including Apporto’s rdp-mgmt-gateway where applicable.

Required ports

Review and approve the required ingress and egress rules before deployment. The exact firewall rules depend on the selected architecture, hypervisor, gateway, directory services, and workload design.

Direction

Component

Source or destination

Port

Protocol

Purpose

Direction

Component

Source or destination

Port

Protocol

Purpose

Ingress

Apporto appliance

Admin network

443

TCP

Cluster node management interface

Ingress

Apporto appliance

Secure gateway or load balancer

30443

TCP

HTTP traffic for Apporto hyperstream and related services

Ingress

Apporto secure gateway

Admin network

8443

TCP

Management interface for the secure gateway

Ingress

Apporto secure gateway

User network

443

TCP

User-initiated traffic to the Apporto hyperstream cluster

Egress

Apporto appliance and secure gateway

DNS servers

53

TCP/UDP

DNS resolution in the local environment

Egress

Apporto appliance and secure gateway

NTP servers

123

UDP

Time synchronization

Egress

Apporto appliance

Active Directory

389, 636

TCP

Directory integration as required by the customer environment

Egress

Apporto appliance and secure gateway

Public IPs

443

TCP

Apporto-required public services, including container registries and management services

Egress

Apporto appliance

VDI/RDSH servers

3389

TCP

RDP access to VDI/RDSH servers used with hyperstream

Egress

Apporto appliance

Nutanix Prism

9440

TCP

Nutanix management API access, required when using Nutanix

Egress

Apporto appliance

VMware vCenter

443

TCP

VMware management API access, required when using VMware

Certificates

Apporto NextGen requires SSL certificates to secure traffic. If you use your own gateway or load balancer, install the required SSL certificate in the appliance or platform that terminates traffic.

Confirm the certificate common name or SANs, issuing certificate authority, private key availability, certificate chain, expiration date, and renewal owner before installation.

Policy baseline

Apply the Apporto policy baseline to RDS servers and VDI desktops to optimize remote session performance, graphics behavior, security, and profile management. The detailed Group Policy Object settings are maintained on the dedicated GPO page instead of duplicated here.

For the complete policy table, see https://apportoteam.atlassian.net/wiki/spaces/APPORTO/pages/2110816257

At a minimum, confirm that the baseline covers:

  • Remote session environment and graphics optimization settings.

  • RDP security layer, encryption, and network-level authentication requirements.

  • Session limits, Fair Share resource management, and profile management for multi-session deployments.

Additional Microsoft references: